AWSCIO BriefingsRetrospectives

CIO Brief: Managed Threat Detection — Build vs. Buy for AWS

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2017, written in 2026 with the benefit of hindsight.

The short version: Amazon GuardDuty, launched in 2017, watches your AWS accounts for signs of attack and costs relatively little. The decision is not really build versus buy — it is whether you have someone to act on what it finds.

What managed detection gives you

Services like GuardDuty and Microsoft Defender for Cloud detect common attack patterns automatically: stolen credentials, compromised servers, crypto mining, unusual data access. Building comparable detection in-house would require log pipelines, a SIEM, threat intelligence and specialist staff.

Where companies go wrong

  • Turning it on in some accounts or regions but not all.
  • Generating alerts that go to an inbox nobody checks.
  • Assuming detection is the same as response.

Questions to ask your team

  • Is threat detection enabled in every AWS account and region we use?
  • Who receives high-severity alerts, and how fast do they respond — including nights and weekends?
  • What was the last real finding, and what did we do about it?
  • Would a managed detection and response provider be more reliable than our current coverage?

What good looks like

Detection everywhere, alerts routed to a responsible person or provider with defined response times, and a monthly summary of findings and actions to leadership.

The decision

The tools are inexpensive; the people are not. If you lack 24/7 coverage, budget for a managed detection and response service or a retainer that monitors these alerts for you.

amazon guardduty impactAmazon GuardDuty2017

More on this story